16-45
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
78-13315-02
Chapter 16 Configuring Access Control
Configuring and Storing VACLs and QoS ACLs in Flash Memory
Note
VACL and QoS ACL mapping commands (
set qos acl map
and
set security acl map
) are also stored
in the auto-config file. If the VACL and QoS ACL configuration is in Flash memory and you use the
mapping commands, you need to enter the
copy
command to save the configuration to Flash memory.
At this point, the VACL and QoS ACL configuration is no longer in NVRAM, it is saved in the
auto-config file bootflash:switchapp.cfg and will be appended to the NVRAM configuration at system
startup.
After making any additional changes to the VACL and QoS ACL configuration and committing those
changes, you must enter the
copy acl-config
bootflash:switchapp.cfg
command to save the
configuration to the auto-config file.
The auto-config file is synchronized automatically to the standby supervisor engine because
synchronization was enabled.
If you cannot write the VACL and QoS ACL configuration to Flash memory, it is removed from
NVRAM. At this point, the VACL and QoS ACL configuration exists in DRAM only. A system reset
for any reason can cause the VACL and QoS ACL configuration to revert to the default.
Note
If you cannot write the configuration to Flash memory, you must copy the configuration to a file,
make additional room available in Flash memory, and then try to write the VACL and QoS ACL
configuration to Flash memory.
At system startup, if the VACL and QoS ACL configuration location is set to Flash memory but either
the CONFIG_FILE variable is not set or none of the files specified exist, the following syslog message
displays:
1999 Sep 01 17:00:00 %SYS-0-CFG_FLASH_ERR:ACL configuration set to flash but no ACL
configuration file found.
Running with the VACL and QoS ACL Configuration in Flash Memory
After you move the VACL and QoS ACL configuration to Flash memory, QoS ACLs and VACL commit
operations are no longer written to NVRAM. You have to copy the configuration to the Flash file
manually as follows:
•
If you use the
set boot config-register auto-config append
option, the configuration from the
auto-config file is appended to the NVRAM configuration. You then only have to copy the VACL
and QoS ACL configuration to this file after commit operations.
•
If you do not use the
set boot config-register auto-config append
option, the auto-config feature
clears the configuration before executing the auto-config file at system startup. Any changes made
in NVRAM are lost. You should always copy your entire configuration (not just the VACL and QoS
ACL configuration) to the auto-config file when you want to save it.